T08 · Insecure Dependencies
- Location
README.md:10- Finding
Unpinned Package Execution Through Mutable Latest Release
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 8–11
Vulnerability Type: Unsafe third-party package installation
Risk Level: MediumVulnerable Code
markdown ## Install ```bash npx clawhub@latest install karpathy-llm-wikitext ### Technical Analysis The documented installation command invokes `npx` with the mutable `clawhub@latest` package reference. Depending on the local environment and cache state, `npx` can retrieve and execute package code from the configured npm registry. Because `latest` is a mutable distribution tag rather than a reviewed, immutable version, the code executed by this command can change after the Skill has been audited. The project provides no pinned version, lockfile, package integrity digest, or provenance-verification procedure for this installation path. This creates a supply-chain trust gap: compromise of the package publisher account, registry release channel, or a future package release could cause users following the documented instructions to execute code that was not present during this audit. ### Attack Path 1. An attacker compromises the `clawhub` publishing account or otherwise gains control over the package version referenced by the `latest` distribution tag. 2. The attacker publishes a malicious release and assigns it to `latest`. 3. A user follows the installation instructions and runs `npx clawhub@latest install karpathy-llm-wiki`. 4. `npx` retrieves the attacker-controlled package through the configured package registry. 5. The package's CLI entry point or applicable lifecycle behavior executes with the privileges of the user running the command. 6. The malicious package can access or modify resources available to that user before or while presenting apparently legitimate installation behavior. ### Impact Assessment Successful exploitation could provide arbitrary code execution with the permissions of the installing user. The access ...[truncated 639 chars]- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an explicitly reviewed package version, for example:bash npx clawhub@<reviewed-version> install karpathy-llm-wiki - Document the expected package publisher, registry, version, and release provenance so users can verify that they are installing the intended artifact.
- Where supported, verify the package's integrity digest or signed provenance before execution.
- Use lockfiles and reproducible installation procedures in automated or development environments.
- Review new package versions before updating the pinned version rather than automatically following the
latesttag. - Advise users to run installation under a least-privileged account and avoid exposing unnecessary credentials in the installation environment.
- Replace
